# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=602

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 603

---

## [Kibana Connector - Unrecgonized Authentication tyoe](https://discuss.elastic.co/t/kibana-connector-unrecgonized-authentication-tyoe/327916)

<div class="topic-metadata">

**Author:** [@Tiharqa](https://discuss.elastic.co/u/Tiharqa)\
**Replies:** 0\
**Last updated:** [March 17, 2023, 9:50am UTC](https://discuss.elastic.co/t/kibana-connector-unrecgonized-authentication-tyoe/327916 "2023-03-17T09:50:02Z")

</div>

Receiving this message when attempt to test my elastic connector 504 5 .7 .4 unrecognized authentication type xpack.actions.preconfigured: my-email: name: somename actiontypeId : .email config: …

---

## [Unable to index into elasticsearch due to Byte range being out of range](https://discuss.elastic.co/t/unable-to-index-into-elasticsearch-due-to-byte-range-being-out-of-range/327857)

<div class="topic-metadata">

**Author:** [@Shreesh\_Narayanan](https://discuss.elastic.co/u/Shreesh_Narayanan)\
**Replies:** 3\
**Last updated:** [March 17, 2023, 9:44am UTC](https://discuss.elastic.co/t/unable-to-index-into-elasticsearch-due-to-byte-range-being-out-of-range/327857 "2023-03-17T09:44:05Z")

</div>

Hi, I have a log that shows the interface usage (eth0/eth1) at a particular time , it logs in bytes and while logstash is able to parse it , elasticsearch seems to be rejecting it . Any workaround for this ? , in the co…

---

## [Best Practices for Efficient and Effective Log Storage and Retrieval with Elasticsearch and Logstash?](https://discuss.elastic.co/t/best-practices-for-efficient-and-effective-log-storage-and-retrieval-with-elasticsearch-and-logstash/327904)

<div class="topic-metadata">

**Author:** [@LongKang\_Fan](https://discuss.elastic.co/u/LongKang_Fan)\
**Replies:** 6\
**Last updated:** [March 17, 2023, 9:28am UTC](https://discuss.elastic.co/t/best-practices-for-efficient-and-effective-log-storage-and-retrieval-with-elasticsearch-and-logstash/327904 "2023-03-17T09:28:48Z")

</div>

Hello, I am currently working with Elasticsearch to store our log files. I have followed all the necessary steps (Filebeat -\> Logstash -\> Elasticsearch) and I am ready to deploy the system for testing before deploying i…

---

## [Creating visualization with the single logline message](https://discuss.elastic.co/t/creating-visualization-with-the-single-logline-message/327417)

<div class="topic-metadata">

**Author:** [@prashant1](https://discuss.elastic.co/u/prashant1)\
**Replies:** 6\
**Last updated:** [March 17, 2023, 9:21am UTC](https://discuss.elastic.co/t/creating-visualization-with-the-single-logline-message/327417 "2023-03-17T09:21:55Z")

</div>

We have one usecase to create the visualization We have below fields in one log message :- requestedMsgCount 2500 allowedMsgCount 2400 startedMsgCount 2400 lostMsgCount 10 terminatedMsgC…

---

## [Elastic SQL](https://discuss.elastic.co/t/elastic-sql/327525)

<div class="topic-metadata">

**Author:** [@\_baba](https://discuss.elastic.co/u/_baba)\
**Replies:** 6\
**Last updated:** [March 17, 2023, 8:41am UTC](https://discuss.elastic.co/t/elastic-sql/327525 "2023-03-17T08:41:00Z")

</div>

Hi, I'm not able to execute sql queries from kibana on AWS managed Elasticsearch, however I can execute it via REST call. Can someone help me identify what's the root cause of this? Query: POST /\_sql { "query": "SELE…

---

## [Allocation temporarily throttled issue](https://discuss.elastic.co/t/allocation-temporarily-throttled-issue/327629)

<div class="topic-metadata">

**Author:** [@nairobi](https://discuss.elastic.co/u/nairobi)\
**Replies:** 1\
**Last updated:** [March 14, 2023, 6:52am UTC](https://discuss.elastic.co/t/allocation-temporarily-throttled-issue/327629 "2023-03-14T06:52:59Z")

</div>

One of my node down accidently, and it joined cluster few minutes later. After that To allocate shard faster, I changed 'cluster.routing.allocation.node\_concurrent\_incoming\_recoveries' 10 to 50 And below issue happene…

---

## [Auditbeat 7.17 high cpu usage](https://discuss.elastic.co/t/auditbeat-7-17-high-cpu-usage/327900)

<div class="topic-metadata">

**Author:** [@KevinShi](https://discuss.elastic.co/u/KevinShi)\
**Replies:** 0\
**Last updated:** [March 17, 2023, 6:12am UTC](https://discuss.elastic.co/t/auditbeat-7-17-high-cpu-usage/327900 "2023-03-17T06:12:48Z")

</div>

auditbeat configure: auditbeat.modules: - module: auditd resolve\_ids: true failure\_mode: silent backlog\_limit: 8192 rate\_limit: 0 include\_raw\_message: false include\_warnings: false backpressure\_strategy: …

---

## [How to return more than 10k hits in spring boot without changing the index.max\_result\_window from elasticsearch 8.6](https://discuss.elastic.co/t/how-to-return-more-than-10k-hits-in-spring-boot-without-changing-the-index-max-result-window-from-elasticsearch-8-6/327888)

<div class="topic-metadata">

**Author:** [@BEY\_MEHREZ](https://discuss.elastic.co/u/BEY_MEHREZ)\
**Replies:** 0\
**Last updated:** [March 16, 2023, 10:00pm UTC](https://discuss.elastic.co/t/how-to-return-more-than-10k-hits-in-spring-boot-without-changing-the-index-max-result-window-from-elasticsearch-8-6/327888 "2023-03-16T22:00:33Z")

</div>

Hello ! I want to return all the documents matching my query but the limit is set to 10k ? What can I do to return all the documents ( they are so much higher than 10k documents) without changing the index.max\_result\_wi…

---

## [Add field with same value for all docs in the index](https://discuss.elastic.co/t/add-field-with-same-value-for-all-docs-in-the-index/327880)

<div class="topic-metadata">

**Author:** [@fzar](https://discuss.elastic.co/u/fzar)\
**Replies:** 0\
**Last updated:** [March 16, 2023, 8:25pm UTC](https://discuss.elastic.co/t/add-field-with-same-value-for-all-docs-in-the-index/327880 "2023-03-16T20:25:01Z")

</div>

Hello, I am writing to ask you about a question regarding the correct approach to take in these cases. We have reports that have a country by default (it is defined when the report is defined) and we have an index that …

---

## [Add new fields based on hostname substring](https://discuss.elastic.co/t/add-new-fields-based-on-hostname-substring/327845)

<div class="topic-metadata">

**Author:** [@lemospt](https://discuss.elastic.co/u/lemospt)\
**Replies:** 4\
**Last updated:** [March 16, 2023, 7:41pm UTC](https://discuss.elastic.co/t/add-new-fields-based-on-hostname-substring/327845 "2023-03-16T19:41:53Z")

</div>

Hi guys, i want to add new fields based on the information in hostname. Below the examples of what i need, hostname=alfrdnsresolverfixed01 new fields: site=alfr, dns\_type=fixed hostname=boavdnsresolvermbbnat01 new f…

---

## [Winlogbeat logs only show that it is 6kb](https://discuss.elastic.co/t/winlogbeat-logs-only-show-that-it-is-6kb/327789)

<div class="topic-metadata">

**Author:** [@iqworks](https://discuss.elastic.co/u/iqworks)\
**Replies:** 8\
**Last updated:** [March 16, 2023, 7:25pm UTC](https://discuss.elastic.co/t/winlogbeat-logs-only-show-that-it-is-6kb/327789 "2023-03-16T19:25:08Z")

</div>

Hi, I am trying to get my Sysmon data to winlogbeat and then to security onion. (unfortunatly, the sysmon.xml and winlogbeat.yml are too big to put here. I wish i could just attach them as files) I am having two issues…

---

## [The get api for kibana spaces doesn't seem to work for python script](https://discuss.elastic.co/t/the-get-api-for-kibana-spaces-doesnt-seem-to-work-for-python-script/327872)

<div class="topic-metadata">

**Author:** [@Bhrugu\_Sharma](https://discuss.elastic.co/u/Bhrugu_Sharma)\
**Replies:** 2\
**Last updated:** [March 16, 2023, 6:38pm UTC](https://discuss.elastic.co/t/the-get-api-for-kibana-spaces-doesnt-seem-to-work-for-python-script/327872 "2023-03-16T18:38:33Z")

</div>

i need to get the spaces from my kibana and i am writing my python code for that import requests response = requests.get('https://\<correct ELASTICSEARCH URL\>:443/api/spaces/space', auth=HTTPBasicAuth('elastic', 'CORREC…

---

## [\[BUG\] Metricbeat stops generating the right timestamp after a while](https://discuss.elastic.co/t/bug-metricbeat-stops-generating-the-right-timestamp-after-a-while/327778)

<div class="topic-metadata">

**Author:** [@vhenriquez](https://discuss.elastic.co/u/vhenriquez)\
**Replies:** 1\
**Last updated:** [March 16, 2023, 6:25pm UTC](https://discuss.elastic.co/t/bug-metricbeat-stops-generating-the-right-timestamp-after-a-while/327778 "2023-03-16T18:25:09Z")

</div>

Metricbeat 8.6 (and possibly other 8.x versions) stops sending the right timestamp after a while. When metricbeat starts running, the timestamps sent to Logstash are correct, but after several hours without restarting t…

---

## [Heartbeat stops pinging http(s) routes](https://discuss.elastic.co/t/heartbeat-stops-pinging-http-s-routes/325181)

<div class="topic-metadata">

**Author:** [@ppic](https://discuss.elastic.co/u/ppic)\
**Replies:** 7\
**Last updated:** [March 16, 2023, 5:39pm UTC](https://discuss.elastic.co/t/heartbeat-stops-pinging-http-s-routes/325181 "2023-03-16T17:39:06Z")

</div>

Hello, I have installed heartbeat (heartbeat-7.17.6-windows-x86\_64) in order to monitor the availability of some URLs. The pb is that it stops pinging without apparent reason (I see nothing special in the logs) while t…

---

## [Reindex API not distributing load when using slicing](https://discuss.elastic.co/t/reindex-api-not-distributing-load-when-using-slicing/325770)

<div class="topic-metadata">

**Author:** [@jmench](https://discuss.elastic.co/u/jmench)\
**Replies:** 3\
**Last updated:** [March 16, 2023, 5:25pm UTC](https://discuss.elastic.co/t/reindex-api-not-distributing-load-when-using-slicing/325770 "2023-03-16T17:25:29Z")

</div>

I have an index with 3 nodes running, each node having 1 primary and 1 replica shard: index shard prirep state node source-index 0 p STARTED eck-elasticsearch-es-default-2 source-index 0 r STA…

---

## [Elasticsearch getting failed to start the service](https://discuss.elastic.co/t/elasticsearch-getting-failed-to-start-the-service/327646)

<div class="topic-metadata">

**Author:** [@Sarathsoundar](https://discuss.elastic.co/u/Sarathsoundar)\
**Replies:** 6\
**Last updated:** [March 16, 2023, 4:19pm UTC](https://discuss.elastic.co/t/elasticsearch-getting-failed-to-start-the-service/327646 "2023-03-16T16:19:31Z")

</div>

Below i mentioned error log for elasticsearch. I don't know how to resolve this, Please anybody help me to resolve this ASAP. Because i want to start this in development server. \<The job identifier is 14563 and the …

---

## [How to map C# DateTime property to @timestamp field](https://discuss.elastic.co/t/how-to-map-c-datetime-property-to-timestamp-field/327866)

<div class="topic-metadata">

**Author:** [@shelby](https://discuss.elastic.co/u/shelby)\
**Replies:** 0\
**Last updated:** [March 16, 2023, 3:14pm UTC](https://discuss.elastic.co/t/how-to-map-c-datetime-property-to-timestamp-field/327866 "2023-03-16T15:14:25Z")

</div>

I am trying unsuccessfully to se the c# client to bluk insert data into elasticsearch. the client connects successfully, however I now have an issue with the following code: var settings = client.ElasticsearchClientSe…

---

## [Upgrade Assistant - Critical Errors!](https://discuss.elastic.co/t/upgrade-assistant-critical-errors/327650)

<div class="topic-metadata">

**Author:** [@Arunaps](https://discuss.elastic.co/u/Arunaps)\
**Replies:** 1\
**Last updated:** [March 16, 2023, 3:11pm UTC](https://discuss.elastic.co/t/upgrade-assistant-critical-errors/327650 "2023-03-16T15:11:17Z")

</div>

Hi, We are trying to upgrade our ELK from 7.17 to 8.6 using upgrade Assistant. It is showing critical alert in Kibana and as follows:- Configuring the "container ID" field has been deprecated and will be removed in 8.…

---

## [Analyze API in NodeJS](https://discuss.elastic.co/t/analyze-api-in-nodejs/327666)

<div class="topic-metadata">

**Author:** [@tirth\_pipalia](https://discuss.elastic.co/u/tirth_pipalia)\
**Replies:** 4\
**Last updated:** [March 16, 2023, 3:07pm UTC](https://discuss.elastic.co/t/analyze-api-in-nodejs/327666 "2023-03-16T15:07:17Z")

</div>

I added html\_strip ad analyzer in the settings of an index. const esObject = { analyzer: 'html\_analyzer', text: ' This is Bold , }; So as per documentation this work in my Kibana Console but I want to use GET \_index…

---

## [Snakeyaml vulnerability (CVE-2022-1471) on latest ES version](https://discuss.elastic.co/t/snakeyaml-vulnerability-cve-2022-1471-on-latest-es-version/327854)

<div class="topic-metadata">

**Author:** [@Aviv\_Nevo](https://discuss.elastic.co/u/Aviv_Nevo)\
**Replies:** 1\
**Last updated:** [March 16, 2023, 3:02pm UTC](https://discuss.elastic.co/t/snakeyaml-vulnerability-cve-2022-1471-on-latest-es-version/327854 "2023-03-16T15:02:50Z")

</div>

Hi Need help regarding CVE-2022-1471 (snakeyaml): Is there any fix for that in any ES version? AFAIK, in the latest version, this package hasn't been updated. Is there any plan to update the damaged package of snakey…

---

## [Fixing snakeyaml vulnerability (CVE-2022-1471) on older ES versions](https://discuss.elastic.co/t/fixing-snakeyaml-vulnerability-cve-2022-1471-on-older-es-versions/327571)

<div class="topic-metadata">

**Author:** [@Aviv\_Nevo](https://discuss.elastic.co/u/Aviv_Nevo)\
**Replies:** 5\
**Last updated:** [March 16, 2023, 3:02pm UTC](https://discuss.elastic.co/t/fixing-snakeyaml-vulnerability-cve-2022-1471-on-older-es-versions/327571 "2023-03-16T15:02:45Z")

</div>

I'm using ES version 5.6.X, and I would like to change snakeyaml package version to the one with the fix to CVE-2022-1471 - Meaning, I need to change the package version from 1.33 (I guess..) to 2.0 . How can I do that? …

---

## [Using rank\_feature to achieve lower boosting the higher the value is](https://discuss.elastic.co/t/using-rank-feature-to-achieve-lower-boosting-the-higher-the-value-is/327860)

<div class="topic-metadata">

**Author:** [@Mustachipleb](https://discuss.elastic.co/u/Mustachipleb)\
**Replies:** 0\
**Last updated:** [March 16, 2023, 2:16pm UTC](https://discuss.elastic.co/t/using-rank-feature-to-achieve-lower-boosting-the-higher-the-value-is/327860 "2023-03-16T14:16:44Z")

</div>

I have an index with a rank\_feature field that's either empty, or a positive integer. In my case, 1 represents the most relevant document within the rank's context, while higher numbers represent lower relevance. I'd lik…

---

## [Cannot append\_fields on custom template](https://discuss.elastic.co/t/cannot-append-fields-on-custom-template/327855)

<div class="topic-metadata">

**Author:** [@GeorgeGkinis](https://discuss.elastic.co/u/GeorgeGkinis)\
**Replies:** 1\
**Last updated:** [March 16, 2023, 2:00pm UTC](https://discuss.elastic.co/t/cannot-append-fields-on-custom-template/327855 "2023-03-16T14:00:54Z")

</div>

Hello! I am using filebeat 7.17.6 and I am using the nginx module. I have altered the access log pipeline to include additional fields. Everything is grokked fine. My issue is that when i define the additional fields…

---

## [Difference between HTTP and Transport certificates](https://discuss.elastic.co/t/difference-between-http-and-transport-certificates/327839)

<div class="topic-metadata">

**Author:** [@divadpoc](https://discuss.elastic.co/u/divadpoc)\
**Replies:** 2\
**Last updated:** [March 16, 2023, 1:53pm UTC](https://discuss.elastic.co/t/difference-between-http-and-transport-certificates/327839 "2023-03-16T13:53:25Z")

</div>

I've found this topic regarding automation of http certificate creation: generate http certificate non interactive, as I was wondering the same thing: why can't I use the same advanced feature of using a yaml file contai…

---

## [Logstash performance issues](https://discuss.elastic.co/t/logstash-performance-issues/327679)

<div class="topic-metadata">

**Author:** [@AKAM14](https://discuss.elastic.co/u/AKAM14)\
**Replies:** 9\
**Last updated:** [March 16, 2023, 1:50pm UTC](https://discuss.elastic.co/t/logstash-performance-issues/327679 "2023-03-16T13:50:28Z")

</div>

Hi , I Have a Logstash 7.17 version , i have two logstash servers in my Setup that gets connected to a 3 node ELK Cluster. One Kibana server We are experiencing less data getting populated in the kibana dashboards. wh…

---

## [Adding a low configuration server as an additional node to elasticsearch cluster?](https://discuss.elastic.co/t/adding-a-low-configuration-server-as-an-additional-node-to-elasticsearch-cluster/327794)

<div class="topic-metadata">

**Author:** [@Shreesh\_Narayanan](https://discuss.elastic.co/u/Shreesh_Narayanan)\
**Replies:** 6\
**Last updated:** [March 16, 2023, 1:16pm UTC](https://discuss.elastic.co/t/adding-a-low-configuration-server-as-an-additional-node-to-elasticsearch-cluster/327794 "2023-03-16T13:16:14Z")

</div>

Hi , I have a single node elasticsearch cluster that may be having slow indexing performance (we have logstash's batch size about 2000 and workers at 40 pushing data to elasticsearch single node), so we were thinking to…

---

## [Error in running Detection Rules Indicator Match](https://discuss.elastic.co/t/error-in-running-detection-rules-indicator-match/327853)

<div class="topic-metadata">

**Author:** [@viera120](https://discuss.elastic.co/u/viera120)\
**Replies:** 0\
**Last updated:** [March 16, 2023, 12:47pm UTC](https://discuss.elastic.co/t/error-in-running-detection-rules-indicator-match/327853 "2023-03-16T12:47:59Z")

</div>

We are running Detection Rules to search for IOCs in firewall logs (using Indicator Matching). The firewall logs have a field named service. Every time there is a match the following error is seen: Bulk Indexing of sign…

---

## [Vectorizing documents - very slow](https://discuss.elastic.co/t/vectorizing-documents-very-slow/327710)

<div class="topic-metadata">

**Author:** [@Cole\_Crawford](https://discuss.elastic.co/u/Cole_Crawford)\
**Replies:** 4\
**Last updated:** [March 16, 2023, 12:07pm UTC](https://discuss.elastic.co/t/vectorizing-documents-very-slow/327710 "2023-03-16T12:07:36Z")

</div>

I am trying to create an NLP pipeline using Charangan/MedBERT · Hugging Face. Ingesting documents with this model and an ES ML pipeline is running very slowly: With a dockerized setup on my local machine with 10GB of RAM…

---

## [New build docker-compose multi-node cluster fails to retrieve password hash for reserved user \[elastic\] / at least one primary shard for the index \[.security-7\] is unavailable](https://discuss.elastic.co/t/new-build-docker-compose-multi-node-cluster-fails-to-retrieve-password-hash-for-reserved-user-elastic-at-least-one-primary-shard-for-the-index-security-7-is-unavailable/326389)

<div class="topic-metadata">

**Author:** [@cookersjs](https://discuss.elastic.co/u/cookersjs)\
**Replies:** 3\
**Last updated:** [March 16, 2023, 11:07am UTC](https://discuss.elastic.co/t/new-build-docker-compose-multi-node-cluster-fails-to-retrieve-password-hash-for-reserved-user-elastic-at-least-one-primary-shard-for-the-index-security-7-is-unavailable/326389 "2023-03-16T11:07:35Z")

</div>

Hi there, I've been following the instructions from Install Elasticsearch with Docker | Elasticsearch Guide \[8.6\] | Elastic (#docker-compose-file for multi-node cluster) and I keep running into an error that seems commo…

---

## [Lag in Logs](https://discuss.elastic.co/t/lag-in-logs/327840)

<div class="topic-metadata">

**Author:** [@kriti\_dabas](https://discuss.elastic.co/u/kriti_dabas)\
**Replies:** 0\
**Last updated:** [March 16, 2023, 10:23am UTC](https://discuss.elastic.co/t/lag-in-logs/327840 "2023-03-16T10:23:29Z")

</div>

Why is there a lag in my logs that too for a particular group? I have four kafka consumer groups out of which one group is not giving real-time logs. There is a one hour delay in the working hours whenever I monitor th…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=601)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=603)
